Keeping WordPress secure means staying alert to new plugin vulnerabilities. This week, several notable threats were disclosed, including a critical CSRF flaw in Avada Core.

CSRF attacks rely on trust, so learn how to recognise the risk and stay protected. (see below)

This plugin could allow a higher privileged users to execute unwanted actions under their current authentication.

Avada Core Plugin
CSRF; 9.6/10; Update to v5.15.7+; Recurring

Editor Comment

It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

Millions of sites use the plugins below, and two vulnerabilities still remain unpatched.

Payment Plugins for Stripe WooCommerce Plugin
Broken Access Control; 7.5/10; Update to v4.0.8+

Hide My WP Ghost Plugin
Broken Authentication; 7.4/10; Update to v7.0.07+; Recurring

Complianz Plugin
PHP Object Injection; 7.2/10; No fix; Remove/or replace.

MailPoet Plugin
CSRF; 7.1/10; Update to v5.33.1+

Contact Form 7 – Dynamic Text Extension Plugin
Content Injection; 6.5/10; No fix; Remove/or replace.

Orbit Fox by ThemeIsle Plugin
XSS; 5.9/10; Update to v3.0.8+

WP Activity Log Plugin
CSRF; 5.4/10; Update to v5.6.5+; Recurring

WP Go Maps Plugin
Broken Access Control; 5.3/10; Update to v10.1.06+; Recurring

Event Tickets Plugin
Broken Access Control; 5.3/10; Update to v5.29.1+; Recurring

GutenKit Plugin
Broken Access Control; 5.3/10; Update to v2.4.13+

Polylang Plugin
Sensitive Data Exposure; 4.3/10; Update to v3.8.6+

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

These plugins may be less common, but the potential damage is significant.

Participants Database Plugin
Arbitrary File Deletion; 10/10; Update to v2.7.8.4+

Advanced Views Plugin
RCE; 9.9/10; Update to v3.9.0+

Thrive Quiz Builder Plugin
PHP Object Injection; 9.8/10; Update to v10.9.3.1+

SMS Alert Order Notifications Plugin
Privilege Escalation; 9.8/10; Update to v3.9.7+; Recurring

rtMedia for WordPress, BuddyPress and bbPress Plugin
SQL Injection; 9.3/10; Update to v4.7.11+

GamiPress Plugin
SQL Injection; 9.3/10; Update to v7.9.8+

Lumise Product Designer Plugin
SQL Injection; 9.3/10; Update to v2.1.2+; Recurring

AWP Classifieds Plugin
SQL Injection; 9.3/10; Update to v4.4.8+; Recurring

MapSVG Plugin
SQL Injection; 9.3/10; Update to v8.14.1+; Recurring

Editor Comment
It’s worth taking a few minutes each week to perform a sites review to catch issues early and wherever possible, use ShieldPRO’s auto-upgrade feature for vulnerable plugins.

#4 – Our blog: Detecting and Preventing WordPress CSRF Vulnerabilities

Fix ‘No anti-CSRF tokens found’ WordPress warnings. Learn why nonces protect forms, test vulnerabilities in minutes, and implement proper validation.

More Info →

Thanks for reading, and have a wonderful week!

Paul Goodchild
Shield Security for WordPress